57,566 vulnerabilities published in 2026
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as p
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricte
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbi
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the inten
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module roo
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses co
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix o
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticat
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of
phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The admin
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenti
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access s
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows a
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response acti
A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown func
Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner
Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet pres
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields fro
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership duri
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 20
In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves th
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role a
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attack
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate EHT MLE before MLD ID read
In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDE
In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: avoid OOB read of num_dests head
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix overflow in passthrough ioctl boun
In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from firmware count in
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix OOB read from firmware RX descript
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own f
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the G
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted Z
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started